project-migration

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent for project migration and uses plausible same-org repos for blueprints/state, with no clear credential theft or exfiltration. However, it includes transitive skill installation via `npx skills add`, expanding trust and permissions beyond basic migration, so the overall risk is medium rather than benign.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/loxosceles%2Fai-dev%2Fproject-migration%2F@313fc9cae7993923731d9d47b225cb0558566dc7